It Depends

A tool to automatically build a dependency graph and Software Bill of Materials (SBOM) for packages and arbitrary source code repositories.

Cybersecurity & Ethical HackingPythonLGPL-3.0

Abstract

It Depends is an open-source Cybersecurity & Ethical Hacking project. A tool to automatically build a dependency graph and Software Bill of Materials (SBOM) for packages and arbitrary source code repositories. It-Depends is a tool to automatically build a dependency graph and Software Bill of Materials (SBOM) for packages and arbitrary source code repositories. It supports Go, JavaScript, Rust, Python, C/C++ (cmake and autotools), and Ubuntu packages. It is built using Python. The complete source code is publicly available on GitHub under the GNU Lesser General Public License v3.0, making it a useful reference for students building a Cybersecurity & Ethical Hacking mini project or final-year project.

1. Introduction

It-Depends is a tool to automatically build a dependency graph and Software Bill of Materials (SBOM) for packages and arbitrary source code repositories. It supports Go, JavaScript, Rust, Python, C/C++ (cmake and autotools), and Ubuntu packages.

2. Objective

A tool to automatically build a dependency graph and Software Bill of Materials (SBOM) for packages and arbitrary source code repositories.

This project demonstrates how Python can be applied to a real-world Cybersecurity & Ethical Hacking problem.

4. Technology Stack

Python

5. System Requirements

General requirements for this technology stack — check the README for exact versions.

  • Python 3.8 or later
  • pip / virtualenv for dependencies
  • VS Code, PyCharm or Jupyter Notebook
  • Git (to clone the repository)

6. Installation & Setup

git clone https://github.com/trailofbits/it-depends.git
cd it-depends
pip3 install it-depends
it-depends .                        # Analyze current directory
it-depends . --list                 # List compatible resolvers
it-depends /path/to/project         # Analyze a different repository

it-depends "pip:numpy"              # Analyze a pip package
it-depends "ubuntu:libc6@2.35"      # Analyze a Ubuntu package
it-depends "npm:lodash@>=4.17.0"    # Specify a version constraint

it-depends --audit "pip:numpy"                          # Include vulnerability audit
it-depends --depth-limit 1 "pip:scikit-learn"           # Only direct dependencies
it-depends --output-format dot --output-file file.dot . # Output as Graphviz/Dot

Full setup instructions are in the project README.

7. Future Enhancements

Suggested extensions you can add to make this your own project.

  • Add logging and alert notifications (email / Telegram)
  • Write a threat model document for the tool
  • Package it with Docker for safe lab testing

8. Viva / Review Questions

Common questions examiners ask for projects in this domain.

  1. Which threat or attack does this project defend against?
  2. What detection or protection technique is used and what are its limits?
  3. How are false positives and false negatives handled?
  4. Which cryptographic algorithms or security standards are involved?
  5. What legal and ethical rules apply when testing a tool like this?

9. Source Code & License

This project is developed by trailofbits and published on GitHub under the GNU Lesser General Public License v3.0. Please follow the license terms and credit the original author when you use or modify this code.

Want to build this as your internship project?

Work on a Cybersecurity & Ethical Hacking project like this with mentor guidance, weekly reviews and an internship certificate from Training Trains, Erode — online or offline.

Apply for Cybersecurity & Ethical Hacking Internship